๐ซ๐ท
SpaceHost-Server
2026-09-20 22:15:35
(2 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
gamabe
2026-09-20 14:26:10
(10 hours ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 13:42:20
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.15.249 (249.15.118.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.15.249 (249.15.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:42:13.161943 2026] [security2:error] [pid 3261:tid 3261] [client 136.118.15.249:50746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "integratic.com.co"] [uri "/@fs/app/.env"] [unique_id "aq_itcVCsugt6tIkv5Ar5AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:10:30
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.15.249 (249.15.118.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.15.249 (249.15.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:10:22.760658 2026] [security2:error] [pid 12550:tid 12550] [client 136.118.15.249:51778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epetsure.co"] [uri "/.github/.env"] [unique_id "aq_bPqTNQp8-T3ZRY1CaCgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-20 12:26:54
(12 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 11:50:55
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.15.249 (249.15.118.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.15.249 (249.15.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:50:51.108822 2026] [security2:error] [pid 24341:tid 24341] [client 136.118.15.249:57842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmexico.co"] [uri "/.env"] [unique_id "aq_Im2e77pKCmqRPJOi3VwAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-20 11:47:10
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
Marten Mark
2026-09-20 11:33:10
(13 hours ago)
136.118.15.249 - - [20/Sep/2026:11:33:09 +0000] "GET /.aws/credentials HTTP/2.0" 404 22988 "-" "Mozi ...
show more
136.118.15.249 - - [20/Sep/2026:11:33:09 +0000] "GET /.aws/credentials HTTP/2.0" 404 22988 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
Web App Attack
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-09-20 11:31:24
(13 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-09-20 11:10:21
(13 hours ago)
buscaempresas.co 136.118.15.249 - - [20/Sep/2026:06:10:19 -0500] "GET /api/console/api_server?sense_ ...
show more
buscaempresas.co 136.118.15.249 - - [20/Sep/2026:06:10:19 -0500] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env HTTP/2.0" 403 6708 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" MISS
buscaempresas.co 136.118.15.249 - - [20/Sep/2026:06:10:20 -0500] "GET /userfiles?path=../../.env HTTP/2.0" 403 6708 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" MISS
buscaempresas.co 136.118.15.249 - - [20/Sep/2026:06:10:20 -0500] "GET /userfiles?path=../../../../.env HTTP/2.0" 403 6708 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" MISS
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 10:49:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.15.249 (249.15.118.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.15.249 (249.15.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 06:49:31.349898 2026] [security2:error] [pid 29887:tid 29887] [client 136.118.15.249:41064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blc2.co"] [uri "/.env.production"] [unique_id "aq-6O3iFN3iKviTxWQKO3QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-09-20 10:43:04
(13 hours ago)
2026/09/20 10:43:02 [error] 478231#478231: *17882740 access forbidden by rule, client: 136.118.15.24 ...
show more
2026/09/20 10:43:02 [error] 478231#478231: *17882740 access forbidden by rule, client: 136.118.15.249, server: binixo.co, request: "GET /.bash_profile HTTP/2.0", host: "binixo.co"
2026/09/20 10:43:02 [error] 478231#478231: *17882740 access forbidden by rule, client: 136.118.15.249, server: binixo.co, request: "GET /@fs/app/.env?raw?? HTTP/2.0", host: "binixo.co"
2026/09/20 10:43:02 [error] 478231#478231: *17882740 access forbidden by rule, client: 136.118.15.249, server: binixo.co, request: "GET /.profile HTTP/2.0", host: "binixo.co"
...
show less
Web App Attack